Google Chrome: 25 Vulnerabilities Patched, Including Critical ANGLE and V8 Flaws
Key findings • Google Chrome patched 25 vulnerabilities on September 29, 2026, including two critical flaws. • Critical vulnerabilities include buffer overflows and use-after-free bugs in ANG…

Key findings
- Google Chrome patched 25 vulnerabilities on September 29, 2026, including two critical flaws.
- Critical vulnerabilities include buffer overflows and use-after-free bugs in ANGLE, Bluetooth, and Views components.
- High-severity flaws in the V8 engine (type confusion) and WebView (authorization) allow for code execution.
- Patches were released in Chrome versions 154.0.8037.92 and 154.0.8037.93 for various operating systems.
- The vulnerabilities affect components like V8, ANGLE, WebView, GPU, and UI elements.
On September 29, 2026, Google released an update for Chrome addressing a significant batch of 25 vulnerabilities, including two critical and multiple high-severity flaws. The vulnerabilities span various components of the browser, such as the V8 JavaScript engine, ANGLE, and WebView, with potential impacts ranging from arbitrary code execution to UI spoofing. This coordinated disclosure highlights ongoing security efforts for the widely used browser.
Several vulnerabilities were identified within Google Chrome's V8 JavaScript engine, a core component responsible for executing JavaScript code. Four distinct type confusion vulnerabilities (CVE-2026-102328, CVE-2026-102326, CVE-2026-102323, and CVE-2026-102321) were disclosed, each carrying a high severity rating and the potential for remote attackers to execute arbitrary code within the sandbox. Additionally, CVE-2026-102324, a use-after-free vulnerability in the PictureInPicture component, also rated high, presents a similar risk.
The ANGLE (Almost Native Graphics Layer Engine) component, which translates graphics commands, was affected by a critical buffer overflow vulnerability (CVE-2026-102331) on Android. This flaw, rated critical, could allow remote attackers to execute arbitrary code outside the sandbox. Another critical vulnerability, CVE-2026-102306, a use-after-free flaw in the Bluetooth module, also poses a significant risk of arbitrary code execution. Furthermore, multiple use-after-free vulnerabilities in the Views component (CVE-2026-102316 and CVE-2026-102308), both rated critical, were patched, with CVE-2026-102316 specifically mentioning social engineering as a potential attack vector.
Other notable vulnerabilities include an incorrect authorization flaw in WebView on Android (CVE-2026-102327), rated high, which could lead to code execution outside the sandbox. Improper privilege management in Mojo on Windows (CVE-2026-102317), also high severity, could allow local attackers to execute arbitrary code. UI misrepresentation flaws were also addressed, including CVE-2026-102314 in TabStrip and CVE-2026-102312 in Omnibox on Android, both allowing remote attackers to spoof UI elements or the address bar, respectively.
The batch of vulnerabilities was fixed in Chrome version 154.0.8037.92 for Windows and Linux, and 154.0.8037.93 for Mac. Google began rolling out these updates on September 29, 2026, with wider distribution expected over the following days and weeks. Users are strongly advised to update their Chrome browsers to the latest version to mitigate these security risks.
This coordinated disclosure of 25 vulnerabilities underscores the continuous need for vigilance in browser security. The variety of vulnerability types and affected components highlights the complex nature of browser security and the importance of regular updates to protect against potential exploitation. Users should ensure their browsers are updated promptly to benefit from these critical security patches.